CWE
284 352
Advisory Published
CVE Published
Advisory Published
Updated

CVE-2016-3729: CSRF

First published: Fri May 13 2016(Updated: )

Multiple vulnerabilities were fixed in moodle 3.0.4, 2.9.6, 2.8.12 and 2.7.14 releases. ============================================================================== MSA-16-0013: Users are able to change profile fields that were locked by the administrator Description: User editing form only disabled the profile fields in UI and did not actually prevent users from editing them Issue summary: Tricky users can change locked profile fields Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Vadim Dvorovenko Issue no.: MDL-53954 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3729">CVE-2016-3729</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-53954">http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-53954</a> ============================================================================== MSA-16-0015: Information disclosure of hidden forum names and sub-names. Description: Name of the inaccessible forum or forum discussion could be disclosed as part of the error message on the subscription page Issue summary: Information disclosure of hidden forum names and sub-names. Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5 and 2.8 to 2.8.11 Versions fixed: 3.0.4, 2.9.6 and 2.8.12 Reported by: Callum Issue no.: MDL-53696 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3731">CVE-2016-3731</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-53696">http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-53696</a> ============================================================================== MSA-16-0016: User can view badges of other users without proper permissions Description: Capability check to view other badges was performed for the current user instead for the user whose badges are being viewed Issue summary: Badges code checks viewotherbadges capability in the wrong context Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6 and 2.8.12 Reported by: Tim Hunt Issue no.: MDL-53589 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3732">CVE-2016-3732</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-53589">http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-53589</a> ============================================================================== MSA-16-0017: Course idnumber not protected from teacher restore Description: During the course restore teacher could overwrite idnumber even without having the capability to change it Issue summary: Course idnumber not protected from teacher restore Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Donna Hrynkiw Issue no.: MDL-51369 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3733">CVE-2016-3733</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-51369">http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-51369</a> ============================================================================== MSA-16-0018: CSRF in script marking forum posts as read Description: CSRF possible in the URL that marks forum posts as read Issue summary: Forum markposts.php missing sesskey check Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Andrew Nicols Issue no.: MDL-53755 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3734">CVE-2016-3734</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-53755">http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-53755</a> ==============================================================================

Credit: secalert@redhat.com secalert@redhat.com

Affected SoftwareAffected VersionHow to fix
Moodle Moodle=2.7.0
Moodle Moodle=2.7.0-beta
Moodle Moodle=2.7.0-rc1
Moodle Moodle=2.7.0-rc2
Moodle Moodle=2.7.1
Moodle Moodle=2.7.2
Moodle Moodle=2.7.3
Moodle Moodle=2.7.4
Moodle Moodle=2.7.5
Moodle Moodle=2.7.6
Moodle Moodle=2.7.7
Moodle Moodle=2.7.8
Moodle Moodle=2.7.9
Moodle Moodle=2.7.10
Moodle Moodle=2.7.11
Moodle Moodle=2.7.12
Moodle Moodle=2.7.13
Moodle Moodle=2.8.0
Moodle Moodle=2.8.1
Moodle Moodle=2.8.2
Moodle Moodle=2.8.3
Moodle Moodle=2.8.4
Moodle Moodle=2.8.5
Moodle Moodle=2.8.6
Moodle Moodle=2.8.7
Moodle Moodle=2.8.8
Moodle Moodle=2.8.9
Moodle Moodle=2.8.10
Moodle Moodle=2.8.11
Moodle Moodle=2.9.0
Moodle Moodle=2.9.1
Moodle Moodle=2.9.2
Moodle Moodle=2.9.3
Moodle Moodle=2.9.4
Moodle Moodle=2.9.5
Moodle Moodle=3.0.0
Moodle Moodle=3.0.0-beta
Moodle Moodle=3.0.0-rc1
Moodle Moodle=3.0.0-rc2
Moodle Moodle=3.0.0-rc3
Moodle Moodle=3.0.0-rc4
Moodle Moodle=3.0.1
Moodle Moodle=3.0.2
Moodle Moodle=3.0.3
redhat/moodle<3.0.4
3.0.4
redhat/moodle<2.9.6
2.9.6
redhat/moodle<2.8.12
2.8.12
redhat/moodle<2.7.14
2.7.14
composer/moodle/moodle>=2.7<2.7.14
2.7.14
composer/moodle/moodle>=2.8<2.8.12
2.8.12
composer/moodle/moodle>=2.9<2.9.6
2.9.6
composer/moodle/moodle>=3.0<3.0.3
3.0.3
=2.7.0
=2.7.0-beta
=2.7.0-rc1
=2.7.0-rc2
=2.7.1
=2.7.2
=2.7.3
=2.7.4
=2.7.5
=2.7.6
=2.7.7
=2.7.8
=2.7.9
=2.7.10
=2.7.11
=2.7.12
=2.7.13
=2.8.0
=2.8.1
=2.8.2
=2.8.3
=2.8.4
=2.8.5
=2.8.6
=2.8.7
=2.8.8
=2.8.9
=2.8.10
=2.8.11
=2.9.0
=2.9.1
=2.9.2
=2.9.3
=2.9.4
=2.9.5
=3.0.0
=3.0.0-beta
=3.0.0-rc1
=3.0.0-rc2
=3.0.0-rc3
=3.0.0-rc4
=3.0.1
=3.0.2
=3.0.3

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203